SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) 2023 mandates comprehensive cybersecurity for all market infrastructure institutions, stock brokers, depositories, and AMCs. Non-compliance risks penalties, trading restrictions, and loss of market participant registration. The framework requires SOC operations, regular audits, and incident response capabilities.
SEBI CSCRF covers 6 domains — governance, identification, protection, detection, response, and recovery. Requirements include mandatory SOC (in-house or managed), vulnerability assessments, penetration testing, cyber audits, incident reporting to SEBI within 6 hours, and business continuity/disaster recovery testing.
We assess your current cybersecurity posture against SEBI CSCRF requirements, identify compliance gaps, and implement controls. We help set up or enhance SOC operations, establish incident reporting workflows, and prepare for SEBI cyber audits. Typical advisory: ₹8-40 lakh depending on market participant category.
Governance, risk, and compliance management
Cloud-based security and compliance scanning
Vulnerability and risk management
Security information and event management
Endpoint security and threat intelligence
Enterprise GRC and risk management platform
Integrated risk and compliance platform
Vulnerability and incident detection
Risk and compliance management platform
Vendor-neutral. Customer-first. We recommend what you need — nothing more.
| SEBI CSCRF Compliance Domain | EDR | NGFW | SIEM | ZT | IAM | DLP | Cloud | DevSec | Backup | GRC | Net | MDR | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| A. Governance | ✓ | ||||||||||||
| B. Asset/Risk | ✓ | ✓ | ✓ | ✓ | |||||||||
| C. SOC | ✓ | ✓ | ✓ | ||||||||||
| D. Data Protection | ✓ | ✓ | ✓ | ||||||||||
| E. Endpoint/App | ✓ | ✓ | |||||||||||
| F. VAPT/Red Team | ✓ | ✓ | ✓ | ||||||||||
| G. Incident Resp | ✓ | ✓ | ✓ | ||||||||||
| H. IAM | ✓ | ✓ | |||||||||||
| I. Third-Party | ✓ | ||||||||||||
| J. Backup/DR | ✓ | ✓ | |||||||||||
| K. Audit | ✓ |